golang-github-lusitaniae-ap.../apparmor-usr.bin.prometheus-apache_exporter

25 lines
540 B
Plaintext

# AppArmor profile for prometheus apache-exporter
#include <tunables/global>
profile /usr/bin/prometheus-apache_exporter flags=(attach_disconnected) {
#include <abstractions/base>
network inet stream,
network inet6 stream,
/etc/ld.so.cache r,
/etc/nsswitch.conf r,
/etc/passwd r,
@{PROC}/sys/net/core/somaxconn r,
@{PROC}/@{pid}/fd/ r,
@{PROC}/@{pid}/{stat,limits} r,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
# grant read access to mtail executable
/usr/bin/prometheus-apache_exporter r,
}